US2022138306A1PendingUtilityA1

Offline multi-factor one-time password authentication

Assignee: ADOBE INCPriority: Nov 5, 2020Filed: Nov 5, 2020Published: May 5, 2022
Est. expiryNov 5, 2040(~14.3 yrs left)· nominal 20-yr term from priority
G06F 21/606G06F 21/36G06F 21/35G06F 21/40G06F 21/602G06F 2221/0755G06F 21/107
36
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A server may encrypt an authentication signal using a public encryption key (e.g., a public encryption key that was generated together with a private encryption key stored on a user device pre-registered with the server). The server passes the encrypted authentication signal to a user agent (e.g., such as the web browser) and the user agent encodes the encrypted authentication signal into a machine-readable optical label. The user agent displays the machine-readable optical label for scanning by the user device. Accordingly, the user device may be unlocked by a user (e.g., using an unlock password or an unlock gesture), and the user device may scan the machine-readable optical label, decode the encrypted authentication signal encoded in the machine-readable optical label, decrypt the decoded authentication signal that was encrypted by the server, and generate an authentication code based on the decrypted authentication signal.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for user authentication, comprising:
 receiving an authentication signal, wherein the authentication signal is encrypted using a public encryption key and encoded as a machine-readable optical label;   decrypting the authentication signal using a private encryption key, wherein the private encryption key is generated together with the public key and stored in a hardware security module of an electronic device; and   generating an authentication code based on the decrypted authentication signal.   
     
     
         2 . The method of  claim 1 , further comprising:
 receiving user input initiating an offline authentication mode, wherein the authentication signal is received according to the offline authentication mode.   
     
     
         3 . The method of  claim 1 , further comprising:
 determining that an unlocking process has been completed for the electronic device containing the hardware security module, wherein the authentication code is generated based on the determination.   
     
     
         4 . The method of  claim 1 , further comprising:
 accessing a camera of the electronic device; and   capturing an image of the machine-readable optical label using the camera.   
     
     
         5 . The method of  claim 1 , further comprising:
 decoding the machine-readable optical label to obtain a digital representation of the authentication signal, wherein the authentication signal is decrypted based on the digital representation.   
     
     
         6 . The method of  claim 1 , further comprising:
 entering the authentication code into a code entry page displayed on an external device.   
     
     
         7 . The method of  claim 1 , further comprising:
 registering the electronic device for offline authentication, wherein the private encryption key and the public encryption key are generated based on the registration of the electronic device.   
     
     
         8 . The method of  claim 1 , further comprising:
 registering an additional device for offline authentication, wherein an additional private encryption key and an additional public encryption key are generated based on the registration of the additional device;   receiving an additional authentication signal encrypted using the additional public encryption key;   attempting to decrypt the additional authentication signal encrypted using the private encryption key stored in the local hardware security module of the electronic device; and   determining that the additional authentication signal is invalid based on the attempted decryption.   
     
     
         9 . The method of  claim 1 , wherein:
 the machine-readable optical label comprises a Quick Response (QR) code.   
     
     
         10 . The method of  claim 1 , wherein:
 the authentication code comprises a one-time numerical code.   
     
     
         11 . A method for user authentication, comprising:
 generating an authentication signal using a public encryption key;   displaying a machine-readable optical label representing the authentication signal to the electronic device;   receiving an authentication code from the electronic device in response to displaying the machine-readable optical label, wherein the authentication code is generated using a private encryption key generated together with the public key and stored in a local hardware security module of an electronic device; and   authenticating a user based on the authentication code.   
     
     
         12 . The method of  claim 11 , further comprising:
 receiving user input initiating an offline authentication mode, wherein the authentication signal is generated according to the offline authentication mode.   
     
     
         13 . The method of  claim 11 , further comprising:
 displaying a code entry page, wherein the authentication code is received via the code entry page.   
     
     
         14 . The method of  claim 11 , further comprising:
 determining that the authentication code is valid, wherein the user is authenticated based on the determination.   
     
     
         15 . The method of  claim 11 , further comprising:
 registering the electronic device for offline authentication, wherein the private encryption key and the public encryption key are generated based on the registration of the electronic device.   
     
     
         16 . The method of  claim 15 , further comprising:
 registering an additional device for offline authentication, wherein an additional private encryption key and an additional public encryption key are generated based on the registration of the additional device;   generating an additional authentication signal encrypted using the additional public encryption key; and   displaying an additional machine-readable optical label representing the additional authentication signal to the electronic device.   
     
     
         17 . An apparatus for user authentication, comprising:
 an offline authentication component configured to receive an authentication signal and to generate an authentication code based on the authentication signal, wherein the authentication signal is encrypted using a public key and encoded as a machine-readable optical label; and   a hardware security module configured to decrypt the authentication signal using a private encryption key that is generated together with the public key.   
     
     
         18 . The apparatus of  claim 17 , further comprising:
 a camera configured to capture an image of the machine-readable optical label.   
     
     
         19 . The apparatus of  claim 17 , wherein:
 the machine-readable optical label comprises a Quick Response (QR) code.   
     
     
         20 . The apparatus of  claim 17 , wherein:
 the offline authentication component is further configured to receive user input initiating an offline authentication mode, wherein the authentication signal is received according to the offline authentication mode.

Join the waitlist — get patent alerts

Track US2022138306A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.